An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0471-1 Rating: important References: #1254776 Cross-References: CVE-2025-14372 CVE-2025-14373 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for chromium fixes the following issues: - Chromium 143.0.7499.109 (boo#1254776): * CVE-2025-14372: Use after free in Password Manager * CVE-2025-14373: Inappropriate implementation in Toolbar * third issue with an exploit is known to exist in the wild Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-471=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 ppc64le x86_64): chromedriver-143.0.7499.109-bp156.1.1 chromium-143.0.7499.109-bp156.1.1 References: https://www.suse.com/security/cve/CVE-2025-14372.html https://www.suse.com/security/cve/CVE-2025-14373.html https://bugzilla.suse.com/1254776 . Important update available for openSUSE to fix two critical issues in Chromium with potential exploits present.. openSUSE, chromium, security update, important exploit, software patch. . Severity: Important. LinuxSecurity.com Team
Update to 143.0.7499.109 * High: Under coordination * Medium CVE-2025-14372: Use after free in Password Manager * Medium CVE-2025-14373: Inappropriate implementation in Toolbar. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1077c09b50 2025-12-16 00:46:10.314091+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 43 Version : 143.0.7499.109 Release : 2.fc43 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 143.0.7499.109 * High: Under coordination * Medium CVE-2025-14372: Use after free in Password Manager * Medium CVE-2025-14373: Inappropriate implementation in Toolbar -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 11 2025 Than Ngo - 143.0.7499.109-2 - Enable gtk4 by default * Thu Dec 11 2025 Than Ngo - 143.0.7499.109-1 - Update to 143.0.7499.109 * High: Under coordination * Medium CVE-2025-14372: Use after free in Password Manager * Medium CVE-2025-14373: Inappropriate implementation in Toolbar - Workaround problem of auto dark mode inverting images and making them unreadable * Tue Dec 9 2025 LuK1337 - 143.0.7499.40-2 - Backport Wayland Omnibox bug fix from upstream -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1077c09b50' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 143.0.7499.109 * High: Under coordination * Medium CVE-2025-14372: Use after free in Password Manager * Medium CVE-2025-14373: Inappropriate implementation in Toolbar. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a315866a59 2025-12-15 01:09:59.310429+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 42 Version : 143.0.7499.109 Release : 2.fc42 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 143.0.7499.109 * High: Under coordination * Medium CVE-2025-14372: Use after free in Password Manager * Medium CVE-2025-14373: Inappropriate implementation in Toolbar -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 11 2025 Than Ngo - 143.0.7499.109-2 - Enable gtk4 by default * Thu Dec 11 2025 Than Ngo - 143.0.7499.109-1 - Update to 143.0.7499.109 * High: Under coordination * Medium CVE-2025-14372: Use after free in Password Manager * Medium CVE-2025-14373: Inappropriate implementation in Toolbar - Workaround problem of auto dark mode inverting images and making them unreadable * Tue Dec 9 2025 LuK1337 - 143.0.7499.40-2 - Backport Wayland Omnibox bug fix from upstream -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a315866a59' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves 2 vulnerabilities and has one bug fix can now be installed.. openSUSE security update: security update for chromium ------------------------------------------------------------- Announcement ID: openSUSE-SU-2025-20161-1 Rating: important References: * bsc#1254776 Cross-References: * CVE-2025-14372 * CVE-2025-14373 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has one bug fix can now be installed. Description: This update for chromium fixes the following issues: - Chromium 143.0.7499.109 (boo#1254776): * CVE-2025-14372: Use after free in Password Manager * CVE-2025-14373: Inappropriate implementation in Toolbar * third issue with an exploit is known to exist in the wild Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-55=1 Package List: - openSUSE Leap 16.0: chromedriver-143.0.7499.40-bp160.1.1 chromium-143.0.7499.40-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2025-14372.html * https://www.suse.com/security/cve/CVE-2025-14373.html . Update available for openSUSE to fix important issues in Chromium, addressing security vulnerabilities and bug fixes.. openSUSE security, chromium update, important vulnerabilities, password manager issue, toolbar fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.